Staff
Since ‎11-16-2022
Online

My Stats

  • 176 Posts
  • 32 Solutions
  • 7 Likes given
  • 157 Likes received

jstoner's Bio

I provide security domain expertise on security operations, threat hunting, detection engineering and response. Additionally, I blog about security operations and threat hunting, currently through the New to Chronicle series on https://chronicle.security/blogs. Part of my time is spent creating and developing workshops intended to provide practitioners the opportunity to broaden their skills within SecOps. I also speak at industry symposia including BSides; Vegas and SF; DefCon Packet Hacking Village; FIRST and FIRST Technical Colloquium Amsterdam; SANS THIR, DFIR, Cloud Security Summit and SIEM Summit; Way West Hacking Fest, WiCyS, AISA, Splunk .conf and Google Cloud NEXT. Prior to coming to Google, I was at Splunk and before that ArcSight. I was an APT scenario creator for a Blue Team CTF and can be found on Threads, Bluesky and Mastodon - Infosec Exchange with the same handle as on XTwitter, I just haven't found a permanent home yet.

Badges jstoner Earned

View all badges

Recent Activity

Today we are going to introduce a string function that takes base64 data and decodes it in search and YARA-L rules. While we don’t often see base64 data sitting all by itself within a UDM field, this command is often applied to placeholder variables ...
In our previous two blogs (Part 1 and Part 2), we discussed how to set up and configure an application in Entra ID and assign permissions to access Entra ID and Office 365 events. You might be thinking at this point, I’m here to work with Google SecO...
We’re back with part two of our Entra ID and Office 365 integration into Google SecOps blog. In our previous blog, we focused on creating an application in Entra ID and gathering key values that we will use to set up our feeds. While we created our a...
Recently, I received a question about how Entra ID (formerly Azure Active Directory) and Office 365 can be integrated into the Google Security Operations (SecOps) platform. This isn’t the first time this has been raised and while we do have documenta...
Today we will go deeper into using regular expressions in rules with the introduction of the function re.capture. re.capture provides us a way to extract a portion of a value within a field. From there, we can compare that portion to another value, w...